By Interestana AI Editorial — AI-drafted, human-overseen. How we report
AliExpress Caught Fingerprinting Browsers With Inaudible Sounds

Chinese e-commerce giant AliExpress has been discovered employing a stealthy browser fingerprinting technique that utilizes inaudible sounds, a method that inadvertently revealed itself when it disrupted researcher Matthew Callaghan's Bluetooth headphones. Callaghan, who was investigating the unusual audio behavior, identified two heavily obfuscated JavaScript scripts on the AliExpress homepage. These scripts collectively generated a graph that analyzed WebAudio API readings from visiting browsers. This analysis involved measuring sawtooth waves, a common output characteristic of digital audio signals. The purpose of this technique is to create a unique identifier for each browser, a process known as browser fingerprinting, which can be used for tracking users across the web without their explicit consent or knowledge. The interference with Callaghan's headphones occurred because his multipoint headphones are designed to prioritize audio from one device when another device is producing sound. When the AliExpress page was loaded, the browser's audio analysis process, triggered by the scripts, caused his phone's audio to cease playing, only resuming when the AliExpress tab was closed. This incident highlights a sophisticated and covert method of user tracking that operates beyond the range of human hearing. Browser fingerprinting typically involves collecting a variety of browser and device attributes, such as screen resolution, installed fonts, browser plugins, operating system details, and even audio hardware capabilities, to construct a unique digital signature for each user. While the specific details of how AliExpress uses these fingerprints were not fully disclosed by the discovery, such practices are often employed for targeted advertising, fraud detection, or to circumvent privacy measures like cookie blocking. The use of the WebAudio API for this purpose is particularly concerning as it leverages a standard web feature for a non-standard, privacy-invasive application. The technique's reliance on analyzing audio output characteristics, even if inaudible, demonstrates an innovative yet intrusive approach to digital surveillance. Callaghan's accidental discovery underscores the ongoing challenges in detecting and mitigating advanced tracking methods employed by online platforms. The incident also raises questions about the ethical implications of using such techniques, especially when they are implemented in a manner that is difficult for users to detect or understand. The effectiveness of this particular method relies on the subtle variations in how different browsers and hardware configurations process and output audio signals, creating a distinct fingerprint for each user session. This discovery adds to a growing body of evidence concerning the pervasive nature of online tracking and the continuous evolution of methods used to collect user data.
Original source — read the full reporting at the publisher:
Read on Ars TechnicaGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.